{"id":7917,"date":"2026-08-10T09:05:57","date_gmt":"2026-08-10T13:05:57","guid":{"rendered":"https:\/\/verito.com\/blog\/?p=7917"},"modified":"2026-08-10T09:33:02","modified_gmt":"2026-08-10T13:33:02","slug":"cyber-insurance-requirements-accounting-firms","status":"publish","type":"post","link":"https:\/\/verito.com\/blog\/cyber-insurance-requirements-accounting-firms\/","title":{"rendered":"What Do Cyber Insurers Require From Accounting Firms in 2026?"},"content":{"rendered":"\n<p><strong>Cyber insurers now ask accounting firms to prove MFA, endpoint detection and response (EDR), encrypted backups, a written incident response plan, documented employee security training, and a Written Information Security Plan (WISP) before binding a policy. Firms that can&#8217;t document these controls face higher premiums, coverage exclusions, or declined renewal.<\/strong><\/p>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>Key takeaways<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Insurers now require six specific controls, up from a one-page form in past renewal cycles.<\/li>\n\n\n\n<li>MFA, EDR, encrypted backups, an incident response plan, security training, and a <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/written-information-security-plan\" target=\"_blank\" rel=\"dofollow noopener\" title=\"WISP\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1353\">WISP<\/a> top the list.<\/li>\n\n\n\n<li>A WISP built for IRS Pub 4557 also covers what insurers and the FTC Safeguards Rule ask for.<\/li>\n\n\n\n<li>Missing controls mean higher premiums, ransomware exclusions, or declined renewal.<\/li>\n\n\n\n<li>VeritShield WISP delivers audit-ready documentation covering both standards in 5 business days.<\/li>\n<\/ul>\n<\/blockquote>\n<\/div><\/div>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-rank-math-toc-block\" id=\"rank-math-toc\"><h2 id=\"table-of-contents\">Table of Contents<\/h2><nav><ul><li><a href=\"#why-did-cyber-insurance-renewal-applications-get-longer\">Why Did Cyber Insurance Renewal Applications Get Longer?<\/a><\/li><li><a href=\"#what-security-controls-do-cyber-insurance-applications-ask-about\">What Security Controls Do Cyber Insurance Applications Ask About?<\/a><\/li><li><a href=\"#how-does-the-ftc-safeguards-rule-connect-to-a-cyber-insurance-application\">How Does the FTC Safeguards Rule Connect to a Cyber Insurance Application?<\/a><\/li><li><a href=\"#does-verito-include-the-controls-cyber-insurers-ask-about\">Does Verito Include the Controls Cyber Insurers Ask About?<\/a><\/li><li><a href=\"#sources\">Sources<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-did-cyber-insurance-renewal-applications-get-longer\"><strong>Why Did Cyber Insurance Renewal Applications Get Longer?<\/strong><\/h2>\n\n\n\n<p><strong>Insurers tightened underwriting across the board because claims data showed most breached firms lacked the controls now being asked about upfront. Accounting firms hold Social Security numbers, bank details, and tax records for hundreds of clients, which puts them under extra scrutiny compared to other small professional services firms.<\/strong><\/p>\n\n\n\n<p>This isn&#8217;t arbitrary. It&#8217;s a direct response to what insurers are paying out on. Firms that get breached usually didn&#8217;t have MFA, EDR, or a documented WISP in place before the incident, so those are exactly the items now showing up on the application.<\/p>\n\n\n\n<p>Firms with 6 to 50 preparers are fielding these longer questionnaires for the first time in 2026, often without a template for how to answer them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-security-controls-do-cyber-insurance-applications-ask-about\"><strong>What Security Controls Do Cyber Insurance Applications Ask About?<\/strong><\/h2>\n\n\n\n<p><strong>Most 2026 applications for professional services firms ask about six specific controls: MFA on email and remote access, EDR on every device, encrypted backups stored separately from production, a written incident response plan, documented annual security training, and a WISP under IRS Publication 4557.<\/strong><\/p>\n\n\n\n<p>The full list, in the order most applications ask for it:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Multi-factor authentication (MFA) on email, remote access, and any system touching client data<\/li>\n\n\n\n<li>Endpoint detection and response (EDR), not just antivirus, on every device<\/li>\n\n\n\n<li>Encrypted backups, stored separately from the production environment<\/li>\n\n\n\n<li>A written incident response plan with named responsibilities<\/li>\n\n\n\n<li>Employee security training, documented and repeated at least annually<\/li>\n\n\n\n<li>A Written Information Security Plan (WISP), the same document the IRS requires under Publication 4557<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa-1024x576.jpg\" alt=\"Multi factor authentication for secure accounting access cinematic visual | Verito\" class=\"wp-image-7930\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-mfa.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>That last item catches most firms off guard. The WISP a firm already needs for IRS compliance is also becoming table stakes for insurance underwriting. A firm with one is most of the way to a clean application. A firm without one is now failing two requirements with a single gap.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-does-the-ftc-safeguards-rule-connect-to-a-cyber-insurance-application\"><strong>How Does the FTC Safeguards Rule Connect to a Cyber Insurance Application?<\/strong><\/h2>\n\n\n\n<p><strong>Firms with 6 to 20 preparers usually know the IRS requires a WISP. Fewer know the FTC Safeguards Rule applies to them too, and insurers are increasingly underwriting to that standard rather than the IRS minimum alone. A WISP built to FTC Safeguards standard covers both requirements at once.<\/strong><\/p>\n\n\n\n<p>The FTC rule is more specific about controls than IRS Pub 4557 alone: MFA, encryption, access controls, and a designated person responsible for the security program. An insurer reading your application is effectively checking whether you&#8217;ve met FTC Safeguards, whether or not the questionnaire names it directly.<\/p>\n\n\n\n<p>The practical upshot: a WISP that only checks the IRS box may not satisfy what your insurer is actually looking for. A WISP built to the FTC Safeguards standard covers both from the start.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp-1024x576.jpg\" alt=\"Protected information security plan for firm compliance cinematic visual | Verito\" class=\"wp-image-7931\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/cyber-insurance-requirements-accounting-firms-wisp.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;The data security Verito provides is immense; it ensures my tax data is secure, eliminating worries about hackers, natural disasters, or computer crashes, offering immense peace of mind.&#8221;<\/em> <\/p><cite>Robin R., Owner, Robin M Rudisill CPA PC \u00b7 G2, Oct 2025<\/cite><\/blockquote><\/figure>\n<\/blockquote>\n\n\n\n<p><strong>What Happens If a Firm Can&#8217;t Answer the Cyber Insurance Questionnaire?<\/strong><\/p>\n\n\n\n<p><strong>Firms that can&#8217;t document these controls typically see one of three outcomes: higher premiums because insurers price in the unknown, coverage exclusions where ransomware payouts are denied if MFA wasn&#8217;t active at the time of the incident, or declined renewal outright. None of this requires an enterprise security budget to fix.<\/strong><\/p>\n\n\n\n<p>The three most common outcomes, in order of severity:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Outcome<\/strong><\/td><td><strong>What triggers it<\/strong><\/td><td><strong>How common<\/strong><\/td><\/tr><tr><td>Higher premiums<\/td><td>Undocumented controls, insurer prices in the unknown<\/td><td>Most common outcome<\/td><\/tr><tr><td>Coverage exclusions<\/td><td>Ransomware claim filed without MFA active at time of incident<\/td><td>Increasingly written into new policies<\/td><\/tr><tr><td>Declined renewal<\/td><td>No documented WISP on file<\/td><td>Increasingly common for smaller firms<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Fixing this requires documentation and a handful of specific controls, most of which a hosting or IT partner should already be handling as part of the environment, not as a separate project.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"does-verito-include-the-controls-cyber-insurers-ask-about\"><strong>Does Verito Include the Controls Cyber Insurers Ask About?<\/strong><\/h2>\n\n\n\n<p><strong>Yes. Firms hosted on <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/veritspace\" target=\"_blank\" rel=\"dofollow noopener\" title=\"VeritSpace\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1352\">VeritSpace<\/a> or bundled under VeritComplete get MFA and endpoint protection built into the environment, not configured as an add-on. VeritShield WISP delivers audit-ready documentation in 5 business days, built to cover IRS Pub 4557 and FTC Safeguards together rather than the IRS minimum alone.<\/strong><\/p>\n\n\n\n<p>When an insurer&#8217;s IT auditor calls with a follow-up question, a firm isn&#8217;t stuck emailing a help desk and waiting. Every ticket reaches a real person in under 60 seconds, with no phone tree and no offshore handoff.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;I&#8217;ve called off season on the weekends. Someone proficient always answers the phone and resolves my issue.&#8221;<\/em><\/p><cite><strong>Irene W., Owner, Wachsler CPA LLC \u00b7 G2, Jul 2025<\/strong><\/cite><\/blockquote><\/figure>\n<\/blockquote>\n\n\n\n<p><strong>How Can a Firm Get Renewal-Ready Before Its Cyber Insurance Application Is Due?<\/strong><\/p>\n\n\n\n<p><strong>The fastest path is comparing the current setup against the six controls insurers actually ask about (MFA, EDR, encrypted backups, an incident response plan, documented training, and a WISP) before the renewal date, not after a declined application. A gap in any one of the six is worth closing before it shows up on paper.<\/strong><\/p>\n\n\n\n<p>Whether the application is due this month or the renewal is six months out, it&#8217;s worth knowing where the gaps are before the insurer finds them. <a href=\"https:\/\/verito.com\/contact\" target=\"_blank\" rel=\"dofollow\" >See what your firm&#8217;s WISP is missing<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"sources\"><strong>Sources<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\" target=\"_blank\" rel=\"nofollow noopener\">IRS Publication 4557, Safeguarding Taxpayer Data<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.ftc.gov\/business-guidance\/privacy-security\/gramm-leach-bliley-act\" target=\"_blank\" rel=\"nofollow noopener\">FTC Safeguards Rule, 16 CFR Part 314<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"Cyber insurers now ask accounting firms to prove MFA, endpoint detection and response (EDR), encrypted backups, a written&hellip;\n","protected":false},"author":12,"featured_media":7928,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-7917","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-knowledge-base"},"acf":[],"_links":{"self":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/7917","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/comments?post=7917"}],"version-history":[{"count":3,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/7917\/revisions"}],"predecessor-version":[{"id":7932,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/7917\/revisions\/7932"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media\/7928"}],"wp:attachment":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media?parent=7917"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/categories?post=7917"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/tags?post=7917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}